Skip to main content

WEBSITE COMPROMISED · FIRST AID

Your website has been hacked: what to do now

The six steps below are the ones that matter in the first hours, in the order they matter. They cost nothing and they work whether or not you ever talk to us. Read them first. What we do is further down, and it is only relevant after the emergency is contained.

The first six steps

  1. Take the site offline behind a maintenance page

    A compromised site keeps working for whoever compromised it: serving malware to your visitors, sending spam from your domain, or hosting a phishing page under your name. Replacing it with a static maintenance page stops the damage from growing while you work out what happened, and it protects the visitors who trusted the address.

  2. Change every password, including the ones nobody thinks of

    The CMS administrator account is the obvious one. The ones that get missed are the hosting control panel, FTP and SFTP accounts, the database user, the DNS registrar and any deploy key or API token the site uses. If the attacker got in once and only the CMS password changes, the way back in is still open.

  3. Tell your hosting provider

    Most hosting providers run an abuse team that has seen the same intrusion many times, can see server-side logs you cannot, and will often isolate the account before the damage spreads to other customers. Calling them early is free and frequently the fastest route to knowing how the attacker got in.

  4. Find a backup from before the incident, not the newest one

    The most recent backup is usually already compromised, because an intrusion is typically discovered days or weeks after it happened. What matters is the last backup taken before the first sign of the attack, which is why the log dates matter more than the backup dates. Restore the newest one and you restore the attacker with it.

  5. Check whether personal data may have been exposed

    If a breach may have put personal data at risk, Article 33 GDPR requires a report to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. In Hesse that authority is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit. Contact forms, customer accounts and shop orders all count as personal data. The clock starts when you become aware, not when you finish investigating.

  6. Decide honestly between cleaning and rebuilding

    Cleaning removes the symptom. If the way in was an outdated plugin, an unpatched core or a weak hosting password, that door is still there after the cleanup, which is why compromised sites are so often reinfected within weeks. Rebuilding on a system with no plugin surface removes the class of entry point instead of the individual infection. Which is right depends on how the attacker got in, and that is the question worth answering before spending money on either.

What Coday does, and what it does not

Coday does not do malware forensics and does not do incident response. During the emergency itself the right people are your hosting provider’s abuse team and, if personal data may be involved, someone who can advise you on the reporting duty. Saying we handle the intrusion would be a claim to a capability we do not have.

What Coday does is the step after: rebuilding the site so the same thing cannot happen the same way. The new site is generated as static files served from an edge network, with no PHP executing on the web server, no plugin ecosystem to keep patched and no database reachable from the public internet. That does not make a website unhackable, because nothing does, but it removes the entry points that automated attacks actually use.

A rebuild after a compromise runs like any other relaunch: every existing address is mapped to its counterpart so the pages you rank for keep an address, the content that earns those positions moves first, and the price is agreed before the work starts. The injected spam URLs are the one addition: those need to stop resolving rather than to be redirected somewhere useful.

Questions after a hack

How did my website get hacked?

The common entry points into a plugin-based CMS are an outdated extension, a core installation that missed a security release, a reused or weak password on the hosting account, and a stolen FTP credential from an infected local machine. In Sucuri’s Website Threat Research Report, which counts the infected sites the company cleaned, around 90 per cent run on WordPress. Not because WordPress is badly built, but because attacks are automated and target whatever is most widespread.

Can I just clean the site and carry on?

Sometimes, and it is worth trying when the entry point is known and closed. It fails when the entry point is unknown, because the cleanup removes the files the attacker left and not the hole they came through. Reinfection within weeks is the usual outcome in that case. The question that decides it is not "is the site clean now" but "do we know how they got in".

Does Coday remove malware from a hacked website?

No. Coday does not do malware forensics or incident response, and saying otherwise would be a claim to a capability it does not have. For the immediate emergency, your hosting provider’s abuse team and a specialist incident responder are the right people. What Coday does is the step after: rebuilding the site on a stack with no plugin surface and no database exposed at the web server, so the class of entry point is gone rather than the individual infection.

Do we have to report a hacked website to the authorities?

A report is required when the breach put personal data at risk. Article 33 GDPR gives 72 hours from becoming aware to notify the competent supervisory authority, and Article 34 additionally requires informing the affected people themselves when the risk to them is high. A site with nothing but static company information and no forms may fall outside this; a site with a contact form, customer accounts or orders almost certainly does not. If you are unsure, that uncertainty is itself a reason to take legal advice quickly rather than to wait.

Will our Google rankings recover after a hack?

Usually, but not on their own and not instantly. A compromised site can be flagged as harmful in Search Console and shown with a warning in results, and the spam pages an attacker injects can be indexed under your domain. Recovery means removing the injected content, requesting a review in Search Console, and making sure the injected URLs return a clear gone-or-not-found status rather than continuing to resolve.

Reply within 24 hours

Your new website : fixed price, built personally by the developer

A website for trades, practices and service providers that loads in under half a second, looks good on every phone and brings in inquiries. Tell me in one sentence what you need; I get back to you within 24 hours.

  1. 1

    Send a quick request

    Name, phone or e-mail, one sentence. That is all.

  2. 2

    Free call within 24 hours

    About 15 minutes: what should the site achieve, who are your customers, what exists already?

  3. 3

    Fixed-price quote

    Binding, no hidden costs. You only pay once you accept it. Live in 10 to 14 business days.

  • Fixed-price guarantee
  • 50% at kick-off, 50% after approval
  • The website belongs to you 100%
See all guarantees
Reply within 24 hours

Quick request

Three fields are enough. I will get back to you personally within 24 hours.

By sending you agree that I use your details to handle your request. No sharing, no advertising. Privacy